An accredited person complies with the data minimisation principle in collecting CDR data only if, when making a consumer data request, it does not seek more data, or data covering a longer period, than is reasonably needed for it (or a relevant CDR representative) to provide the goods or services the consumer asked for. Use or disclosure by an accredited person or CDR representative complies only if the use or disclosure of the collected data, and of anything directly or indirectly derived from it, goes no further than is reasonably needed to provide those goods or services or to carry out the permitted use or disclosure. The principle is the yardstick for consent requests (rules 4.11(3)(c) and 4.12(2)), consumer data requests (rules 4.4 and 4.7A) and permitted uses (rule 7.5(1)(a)).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.